Cybersecurity in Elections: Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies Preface The International Foundation for Electoral Systems (IFES) has worked for more than 30 years in over 145 countries to support the right to free and fair elections worldwide. Securing that right once it has been established is a major part of our work. As technology changes, countries and their election management bodies (EMBs) must change how they conceive of security. Bad actors, whether foreign or domestic, use technology to enhance their reach and the damage they can inflict. Battles for the integrity of elections are increasingly waged in cyberspace, and one small flaw in technology, or in the way it is used, can jeopardize an election. Hence, strengthening cybersecurity in democracies is increasingly important, and IFES is continuing to expand our support to electoral cybersecurity globally. Even as cyberattacks become more frequent, electoral processes are becoming increasingly reliant on the kinds of technology those attacks exploit. Elections increasingly depend on technology such as digital voter rolls and election results, biometric voter registration, and electronic voting machines. Countries are continuing to adopt these technologies, so the need for an effective framework for protecting against cyberthreats has never been greater. This cannot be an afterthought in the electoral process. Rather, a discussion around the ever-changing electoral threat environment should inform the public procurement process for any election technology. To do otherwise is to risk the possibility that actual or perceived vulnerabilities are exploited to undermine the credibility of the process. The balance between transparency and security is perhaps the central issue in cybersecurity in elections. While technology needs to be sufficiently opaque to bad actors, the public can quickly lose trust in any system that is a “black box” to non-experts. Securing this technology means more than just strong software and hardware – it also means securing the human, political, legal and procedural aspects of an election. A technology can only be as secure as the processes and the people around it. Building on case studies and an extensive literature review, IFES has turned its lessons learned into a methodology to assist EMBs in their defense against cyberattacks on the democratic process. The methodology presented in this paper, called the Holistic Exposure and Adaptation Testing (HEAT) process, is a holistic framework for understanding and responding to threats to electoral cybersecurity. Drawing on an extensive literature review and our technical expertise, IFES developed this framework with the shifting technological landscape in mind. The nature of technical innovation means that cyberattacks cannot be wholly prevented, but they can and should be anticipated as much as is possible. The HEAT process is designed to support EMBs in assessing and protecting against cyberthreats. Protecting the fundamental right to free and fair elections now requires a cybersecurity strategy and infrastructure. IFES wrote this paper to that end and will continue defending democratic electoral processes from cyber interference in support of citizens’ right to political participation and representation. William R. Sweeney, Jr. IFES President and CEO 1

Select target paragraph3